1,116 questions with Sysinternals-related tags

Sort by: Updated
1 answer

how to get the loaded assemblies of a process programatically

Reference to this old question : https://stackoverflow.com/questions/36431220/getting-a-list-of-dlls-currently-loaded-in-a-process-c-sharp I am writing a security application where we are monitoring our in house developed software (EPD) which is composed…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2024-06-03T07:53:23.16+00:00
Philip Stuyck 0 Reputation points
edited an answer 2024-06-05T01:17:55.6166667+00:00
Castorix31 82,661 Reputation points
0 answers

Bug in the latest RAMMAP version (v1.61)

There is a bug in RAMMAP v1.61. This bug doesn't crash the program. But it's VERY annoying and needs to be fixed in the next version of RAMMAP. Start the program and open the "Processes" tab. Then you'll see that the program will only displays…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2024-05-31T13:45:23.97+00:00
Willem Grooters 0 Reputation points
edited the question 2024-06-04T11:50:01.41+00:00
Willem Grooters 0 Reputation points
0 answers

Is sdbinst.exe malware if it is using options not listed in MS documentation?

I am using Sysmon and sending the logs to Wazuh for threat detection. It shows a level 12 event that pertains to sdbinst.exe. The event data command line was C:\WINDOWS\System32\sdbinst.exe -m -bg but according to MS documentation the options used by…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2024-06-01T22:12:02.1766667+00:00
SLM64 20 Reputation points
1 answer

How do I hide "Filter by name" in "Process Explorer"

Maybe 6-8 months back, I noticed that a field called "Filter by name" appeared near the upper right corner of the main Process Explorer window. Considering what I use ProcExp for, I rarely need this field to be visible. From what I understand,…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2021-10-15T02:12:47.493+00:00
Frank Wojtczak 6 Reputation points
commented 2024-06-01T13:35:26.3566667+00:00
Bernd Will 0 Reputation points
0 answers

Can Process Monitor watch for DCOM issues?

I was wondering if there was a way to have Process Monitor watch for DCOM issues, like Access Denied. I am asking because I was trying to diagnose an issue with a web service, and eventually discovered that it was a DCOM issue, but unfortunately, the…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2024-05-29T02:08:20.78+00:00
MDell.Seradex 1 Reputation point
0 answers

Black screen when running an application remotely with PSExec

I'm going to run notepad remotely using PSExec with its interactive option as below but the notepad console appears with a black screen: PSExec -i -d \RemoteComputer notepad.exe And the following runs it in the background as SYSTEM and console doesn't…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2022-08-03T21:04:23.707+00:00
EminentX 6 Reputation points
commented 2024-05-27T19:00:23.5933333+00:00
Farhad Shokrpour 0 Reputation points
0 answers

How to fix PsExeSvc.exe %1 není platná aplikace typu Win32. XPe SP3

Please help me howto run psexesvc service. Old psexe.exe works, but display console on host PC.

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2024-05-27T13:48:20.23+00:00
Karel Kadlec 0 Reputation points
1 answer

Can we discriminate the actual reason for the behiavour of defragmentation?

Given that in this deployment history (and previous ones), storage disks analyze much more easily the fragmentation even when heavier with data than the system disk, Is it only the system disk that requires this effort or, like it is reported in…

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
11,028 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2024-05-24T11:13:46.91+00:00
Claus Debanker 21 Reputation points
answered 2024-05-27T08:51:03.88+00:00
Wesley Li 5,960 Reputation points
2 answers

Disk2VHD not starting

Hello forum, I downloaded disk2vhd from the official site. When I start disk2vhd64.exe as admin, I get the dialog to allow making changes to the hard drive, but afterwards nothing happens. Starting disk2vhd.exe results in "Error…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2022-07-23T09:18:05.603+00:00
Johannes Bunte 1 Reputation point
commented 2024-05-24T12:21:11.69+00:00
r2db 0 Reputation points
1 answer

Bginfo and virtual computing

I'm having lots of network adapters show up, and "(null)"s in the related IP address, subnet mask, DHCP Server, etc. fields. I've already done the 'custom variable' thing with the test for IPEnabled=True, but these adapters may be 'real' in…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2022-01-16T17:45:38.8+00:00
Bryan Bentz 1 Reputation point
answered 2024-05-24T09:48:34.8733333+00:00
GreenEyedBoy 0 Reputation points
0 answers

Request for option to carry process creation detail fields into other Sysmon event types

In Sysmon "Process Create" events, the details are invaluable, but many times I have wished that at least key process creation details like CommandLine, ParentImage, ParentCommandLine, and Hashes, could be carried over to other event types that…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2024-05-22T20:25:15.41+00:00
Kevin Branch 0 Reputation points
0 answers

Can the tool 'streams.exe' regard "Scan inside symbolic links" as an optional parameter?

I tried to use the command "streams64.exe -s -d" or "streams.exe -s -d" in Administrator access in the user folder "C:\Users\<username>", However, here is a symbolic link…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2024-05-22T06:59:59.5+00:00
0 0 0 Reputation points
0 answers

Zoomit64 LiveZoom (Ctrl+4) displays a blank, black screen on a Dell XPS 17 9730.

On a Windows 11 23H2 22631.3593. Intel i7-3700H 2.40 GHz laptop, Zoomit64 Live Zoom displays a black screen. Displays are 2 x BenQ 27" monitors via Intel Iris Xe graphics and NVIDIA GeForce RTX 4050 laptop GPU. Connections are via digital DVI.

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2024-05-20T12:18:54.79+00:00
Dave Romig Sr 0 Reputation points
0 answers

SDelete on EFS encrypted folder displaying weird behavior, filling up drives when no clean drive parameter specified

C:\Users\user>sdelete -p 3 -r -s C:\temp\ToDelete SDelete v2.04 - Secure file delete Copyright (C) 1999-2019 Mark Russinovich Sysinternals - www.sysinternals.com SDelete is set for 3 passes. C:\temp\ToDelete\ForDeletion.txt...deleted. …

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2021-04-01T04:23:51.48+00:00
Tan, Yong Kee 6 Reputation points
edited a comment 2024-05-19T15:06:30.8133333+00:00
miwoj 0 Reputation points
1 answer

Manipulating Perfmon data for easy combining and relogging for multiple device comparison.

What I'm trying to do: Perfmon is collecting data from multiple servers. I pulled the .blg files, and then combine them into one file for performance review of multiple servers. I combine the .blg files using the following script: Relog…

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,493 questions
Windows Server PowerShell
Windows Server PowerShell
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.PowerShell: A family of Microsoft task automation and configuration management frameworks consisting of a command-line shell and associated scripting language.
5,443 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2022-08-03T14:45:01.507+00:00
Jose P 21 Reputation points
commented 2024-05-19T07:51:41.01+00:00
Arash Shahkarami 0 Reputation points
0 answers

Has anyone used the "ion-storm" XML configuration with sysmon?

I'm trying to find someone who has used SwiftOnSecuritys "ion-storm" XML configuration with sysmon for event collection and has configured Wazuh rules for the events. I can't figure out how to configure Wazuh to work with the ion-storm agent…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2024-05-17T02:29:26.84+00:00
SLM64 20 Reputation points
1 answer

Does Sysinternals Utilities come installed with Windows

Is it necessary to download Sysinternals Utilities separately or are they already included in Windows? I have searched for an answer but couldn't find anything definitive. Thank you for your help. Nick Putch

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2024-05-16T19:30:57.9166667+00:00
Nputch 0 Reputation points
answered 2024-05-16T19:52:43.0166667+00:00
Andreas Baumgarten 101.2K Reputation points MVP
1 answer

PSTools Error

I have a win11 computer with no access to the internet. cmd is run as administrator. After trying to open a task scheduler via the PSTools on my desktop (psexec.exe -i -s %windir%\system32\mmc.exe /s taskschd.msc) I am getting the following error:…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2024-05-08T03:53:41.0366667+00:00
TommyVercetti 0 Reputation points
commented 2024-05-14T18:53:13.13+00:00
MotoX80 32,551 Reputation points
1 answer

Sysmon 15.12 - high cpu utilization & stops logging certain events

Running sysmon 15.12 with a pretty robust config that's a combination of open source (swiftonsecurity, etc) and my own rules. I am noticing a peculiar behavior in 15.12 where after running normal/stable for a while, sysmon decides to consume an entire…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2024-04-29T23:55:42.9666667+00:00
Gary Portnoy 0 Reputation points
edited a comment 2024-05-14T14:32:39.9833333+00:00
Alex Mihaiuc 176 Reputation points Microsoft Employee
1 answer

FAILURE ( 5627 ): 50: Run DISM.exe - Windows Education x64 - 20H2 Update

Hi all, This whole ordeal is causing me a large headache, I am looking to deploy a SysPrepped image across multiple devices but keep running into this error. Windows Version: Windows 10 Education (20H2 Update) Windows ADK Version: 10.1.19041.1 …

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
asked 2021-06-18T12:49:06.527+00:00
Scott Wilks 6 Reputation points
answered 2024-05-14T07:49:11.5766667+00:00
TaoHuabing-0777 0 Reputation points